feat: harden the RNS carrier: idle-link reaper, refusal logging, patched microReticulum fork

This commit is contained in:
randogoth 2026-09-29 10:27:44 +03:00
parent 07f064460f
commit 8ea6865e7e
6 changed files with 110 additions and 16 deletions

View file

@ -9,8 +9,13 @@
# so every microReticulum FetchContent dependency is vendored as its own
# flake input and handed over via RNS_<DEP>_SOURCE_DIR. microReticulum
# is pinned at the commit RNS.md sec 5 verified against.
# Local fork of attermann/microReticulum at rev 40fa628809d5 plus a
# local patch: Transport::outbound/inbound skip their jobs-cycle wait
# for same-thread reentrant calls, which otherwise deadlock the single
# transport loop when a stalled resource tick sends a RESOURCE_REQ
# from inside jobs() (see RNS.md sec 9).
microReticulum = {
url = "github:attermann/microReticulum/40fa628809d57140180c1c833559ab96fec992c1";
url = "git+file:///mnt/data/Projects/code/microReticulum?ref=fix/outbound-reentrancy-deadlock";
flake = false;
};
rns-arduinojson = {
@ -272,6 +277,15 @@
description = "Max request bytes per minute, per link.";
};
linkIdleSecs = mkOption {
type = types.ints.unsigned;
default = 300;
description = ''
Seconds after which an idle RNS link is reaped, freeing
its session and link slot; 0 disables the reaper.
'';
};
udpListenPort = mkOption {
type = types.port;
default = 4242;
@ -337,6 +351,7 @@
--rns-max-links ${toString cfg.rns.maxLinks}
--rns-rate-link-requests ${toString cfg.rns.rateLinkRequests}
--rns-rate-link-bytes ${toString cfg.rns.rateLinkBytes}
--rns-link-idle ${toString cfg.rns.linkIdleSecs}
--rns-udp 0.0.0.0:${toString cfg.rns.udpListenPort}
)
''}